Ethical Hacking News
A recently uncovered email vulnerability has left numerous Western organizations exposed to cyber threats from Russian-backed attackers. This malicious campaign, attributed to Laundry Bear or Void Blizzard, exploits a Zimbra vulnerability that allows attackers to steal sensitive information from victims' email communications without requiring any user interaction.
A joint security alert has been issued by government agencies in the US, UK, and other countries attributing a year-long wave of attacks to "Laundry Bear" or "Void Blizzard," a group sponsored by Russia. The attackers are exploiting CVE-2025-66376, a cross-site scripting (XSS) vulnerability in Zimbra web-based email and collaboration suite. The attackers send malware-laden emails that exfiltrate sensitive information, including email communications, passwords, and authentication tokens. Artificial intelligence played a role in the development of the malicious framework, which stores stolen data on an unattributable virtual private server. Organizations are advised to minimize use of ZCS webmail client until patched, and stay informed about latest security patches and updates.
In a concerning turn of events, numerous government agencies across the United States, the United Kingdom, and other international entities have issued a joint security alert that attributes a year-long wave of attacks to a group dubbed "Laundry Bear" or "Void Blizzard." These malicious actors, identified as being sponsored by the Russian Federation, have been utilizing an exploitable vulnerability in the Zimbra web-based email and collaboration suite to compromise targets.
The specific vulnerability in question is CVE-2025-66376, a cross-site scripting (XSS) flaw that allows attackers to inject malicious JavaScript into web pages viewed by the victim. Despite the patch being released in November 2025, Moscow's attackers began exploiting this security hole as soon as July 2025.
The Laundry Bear group has been using this vulnerability to send malware-laden HTML email messages to targeted Western organizations, including those in the defense industrial base, federal and local governments, education, energy, law enforcement, media, non-governmental organizations, and technology sectors. These emails do not require any user interaction other than viewing the malicious message, after which the attackers exfiltrate a substantial amount of sensitive information from the victims' email communications.
This stolen data includes the last 90 days of email communications, email addresses and passwords, email directories such as global address lists, two-factor authentication tokens, and newly created application passcodes. The attackers use these stolen credentials to maintain access to the victims' email accounts, modifying account preferences and collecting authentication information.
The malicious emails used in this campaign include specific email addresses such as ivanka.zurabishvili@proton[.]me, zmul1@buildandconsulting[.]com, garrysmithme@pinmx[.]net, and hostingclient@pinmx[.]net. The attackers store the stolen data on an unattributable virtual private server (VPS) running their custom "Flowerbed" collection framework.
Further analysis indicates that artificial intelligence (AI) played a role in the development of this malicious framework, as suggested by the simplistic nature of its codebase and utilization of Docker for containerization. The government agencies have identified indicators of compromise (IOC) to aid organizations in identifying individuals compromised by the Laundry Bear campaign.
To mitigate this threat, it is advised that employees minimize their use of the ZCS webmail client until their organizations update to a patched version that is not vulnerable to CVE-2025-66376. By taking these precautions and staying informed about the latest security patches and updates, organizations can better protect themselves against future attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/New-Email-Vulnerability-Exposes-Western-Organizations-to-Russian-Cyber-Threats-ehn.shtml
https://www.theregister.com/patches/2026/07/23/year-long-russian-attacks-infect-users-as-soon-as-they-look-at-an-email/5277358
https://nvd.nist.gov/vuln/detail/CVE-2025-66376
https://www.cvedetails.com/cve/CVE-2025-66376/
Published: Thu Jul 23 13:04:58 2026 by llama3.2 3B Q4_K_M